PCI DSS v3.2 SAQ B, Rev. 1.1 January 2017
© 2006-2017 PCI Security Standards Council, LLC. All Rights Reserved. Page iii
Before You Begin
SAQ B has been developed to address requirements applicable to merchants who process cardholder
data only via imprint machines or standalone, dial-out terminals. SAQ B merchants may be either brick-
and-mortar (card-present) or mail/telephone order (card-not-present) merchants, and do not store
cardholder data on any computer system.
SAQ B merchants confirm that, for this payment channel:
Your company uses only an imprint machine and/or uses only standalone, dial-out terminals
(connected via a phone line to your processor) to take your customers’ payment card information;
The standalone, dial-out terminals are not connected to any other systems within your environment;
The standalone, dial-out terminals are not connected to the Internet;
Your company does not transmit cardholder data over a network (either an internal network or the
Internet);
Any cardholder data your company retains is on paper (for example, printed reports or receipts),
and these documents are not received electronically; and
Your company does not store cardholder data in electronic format.
This SAQ is not applicable to e-commerce channels.
This shortened version of the SAQ includes questions that apply to a specific type of small merchant
environment, as defined in the above eligibility criteria. If there are PCI DSS requirements applicable to
your environment that are not covered in this SAQ, it may be an indication that this SAQ is not suitable for
your environment. Additionally, you must still comply with all applicable PCI DSS requirements in order to
be PCI DSS compliant.
PCI DSS Self-Assessment Completion Steps
1. Identify the applicable SAQ for your environment – refer to the Self-Assessment Questionnaire
Instructions and Guidelines document on PCI SSC website for information.
2. Confirm that your environment is properly scoped and meets the eligibility criteria for the SAQ you
are using (as defined in Part 2g of the Attestation of Compliance).
3. Assess your environment for compliance with applicable PCI DSS requirements.
4. Complete all sections of this document:
Section 1 (Parts 1 & 2 of the AOC) – Assessment Information and Executive Summary.
Section 2 – PCI DSS Self-Assessment Questionnaire (SAQ B)
Section 3 (Parts 3 & 4 of the AOC) – Validation and Attestation Details and Action Plan for
Non-Compliant Requirements (if applicable)
5. Submit the SAQ and Attestation of Compliance (AOC), along with any other requested
documentation—such as ASV scan reports—to your acquirer, payment brand or other requester.